New Community Ranking System
Our Community ranking system has recently been updated. You may notice changes in user rankings and receive system messages or notifications. If you have questions about how the new ranking works, please refer to the announcement post for more details (click here).
EcoStruxure IT Mobile App SSO Looks Like Man In The Middle Attack To Password Manager
EcoStruxure IT Forum
Schneider Electric support forum about installation and configuration for DCIM including EcoStruxure IT Expert, IT Advisor, Data Center Expert, and NetBotz
Search in
Improve your search experience:
Exact phrase→Use quotes " "(e.g., "error 404")
Wildcard→Use * for partial words(e.g., build*, *tion)
AND / OR→Combine keywords(e.g., login AND error, login OR sign‑in)
Keep it short→Use 2–3 relevant words, not full sentences
Filters→Narrow results by section(Knowledge Base, Users, Products)
Send a co-worker an invite to the portal.Just enter their email address and we'll connect them to register. After joining, they will belong to the same company.
You have entered an invalid email address. Please re-enter the email address.
This co-worker has already been invited to the Exchange portal. Please invite another co-worker.
Please enter email address
Send InviteCancel
Invitation Sent
Your invitation was sent.Thanks for sharing Exchange with your co-worker.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2026-07-1503:45 AM
EcoStruxure IT Mobile App SSO Looks Like Man In The Middle Attack To Password Manager
I have configured our EcoStruxure ITE platform to allow SSO logins using Entra ID for our organisation. This is working for our users logging via a web browser, but we have a problem with logins to the Mobile App and a password manager, 1Password.
When logging in using a web browser a user enters their SSO ID on the 'login.ecostruxureit.com'. It recognises the SSO domain, and redirects to my org's Entra IdP page at 'login.microsoftonline.com'. Once their Entra ID credentials have been provided (either manually typed in, or provided using 1Password) it redirects back to 'app.ecostruxureit.com' with an authenticated session.
However, with the EcoStruxure IT app on iOS we have a security problem. Our users enter their SSO ID on the initial Welcome screen, then our Entra ID page pops up within the Ecostruxure app. If we try to fill the Entra ID details from a password manager such as 1Password we get a security warning that we're sending our credentials to login.ecostruxureit.com, not login.microsoftonline.com
There is a mismatch between the domain configured in the mobile app (login.ecostruxureit.com), and the IdP URL (login.microsoftonline.com), and the password manager app flags this. It looks like a Man In The Middle attack, with login.ecostruxureit.com trying to intercept the user's Entra ID credentials.
Assuming EcoStruxure IT is not intercepting our credentials, we could tell our users that this is okay and to always allow access. But it is bad security practice telling our users to ignore a valid security warning, and it encourages insecure working practices.
The app needs fixing to handle SSO IdP logins correctly, and not have the credentials passed through the Schneider app, similar to how web logins are processed.